References https://nvd.nist.gov/vuln/detail/cve-2022-31279 https://avd.aliyun.com/detail?id=AVD-2022-31279 https://www.cnvd.org.cn/flaw/show/CNVD-2022-44351 https://github.com/advisories/GHSA-vv7q-mfpc-qgm5 https://security.snyk.io/vuln/SNYK-PHP-LARAVELFRAMEWORK-2863117 https://www.miggo.io/vulnerability-database/cve/CVE-2022-31279 https://dbugs.ptsecurity.com/vulnerability/PT-2022-20661 https://blog.lexfo.fr/laravel-debug-rce.html https://www.zongscan.com/demo333/95832.html https://todis21.github.io/2023/08/02/Laravel%E6%BC%8F%E6%B4%9E%E5%90%88%E9%9B%86/
Related VulnerabilitiesPoCCVE-2026-44262: Scramble Laravel - Remote Code ExecutionPoClaravel-ignition-log-viewer: Laravel Ignition - Log Viewer Information DisclosurePoClaravel-clockwork-exposure: Laravel Clockwork - Sensitive Information ExposurePoClaravel-debugbar-exposure: Laravel Debugbar - Sensitive Information ExposurePoClaravel-nova-unauth: Laravel Nova - Unauthenticated Admin Panel AccessPoClaravel-passport-keys-exposed: Laravel Passport - OAuth2 Keys ExposedPoClaravel-pulse-unauth: Laravel Pulse - Unauthenticated Dashboard AccessPoClaravel-sanctum-misconfig: Laravel Sanctum - Stateful Domain CSRF MisconfigurationPoCCVE-2025-54068: Laravel Livewire v3 - Remote Command ExecutionPoClaravel-sessions-exposure: Laravel Sessions Folder ExposurePoClaravel-terminal-exposure: Laravel Terminal - ExposedPoCCVE-2017-16894: Laravel <5.5.21 - Information DisclosurePoCCVE-2021-3129: Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Execution